Like many web applications, Wordpress stores user accounts in a MySQL database, including administrative user accounts with their associated password hashes. A closer inspection of the method chosen for hashing passwords in Wordpress offers an critical view of how secure or insecure the hashing methods in place are for such high profile and widely used software.

Way back as of Wordpress 2.5 (March 2008), phpass has been used to hash passwords for storage in a MySQL database. phpass was written by Alexander Peslyak (aka Solar Designer), founder of the Openwall Project and creator of John the Ripper who is perhaps one of if not the authority on various hashing algorithm technologies. phpass is used by WordPress, Vanilla, phpBB, Drupal, and many other applications for password hashing.

phpass

phpass utilizes three components for password hashing:

Hash algorithm (blowfish, DES, or MD5 in that order if available)

Salt (random unique salt generated for each password)

Iterations or password stretching (a specified number of iterations or rounds set as desired)

To obtain the highest level of security with phpass, the server must be running PHP version 5.3.0 or later. This is because particular PHP algorithm code is only included in 5.3.0 and later. Specifically recommended is PHP 5.3.0 or later with the Suhosin security hardening patch.

Ubuntu and Debian Linux include the Suhosin PHP patch via the package php5-suhosin. Red Hat Enterprise Linux 5 and 6 and likewise CentOS 5 and 6 do not include this patch by default and it must be compiled manually for those distributions. Note that Debian is considering removing Suhosin patched PHP from their distribution, so future patching may be required. Suhosin has unfortunately not been well maintained, so Debian and other distributions are removing its support.

If using PHP 5.3.0 or later with the Suhosin patch, phpass has the ability to hash with blowfish (CRYPT_BLOWFISH in PHP), falling back to DES hashes if using PHP 5.3.0 and no Suhosin patch (CRYPT_EXT_DES in PHP), and a final fallback to salted MD5 based hashes (known as portable hashes). phpass utilizes iterations and salt regardless of which algorithm is utilized.

Regarding salts, phpass takes care of the complexity of adding salt to hashes. The function HashPassword() generates an eight-character random salt for each password, encoding the salt into the returned hash value. The function CheckPassword() checks against the hash that includes the salt, and it just works.

For iterations or rounds, the exact number can be set as desired by the web application. For example Wordpress uses 8192 iterations and Drupal 7 uses 16384 iterations with phpass for password hashes.

Wordpress Hashes

Wordpress has chosen by default to use the final fallback in phpass known as 'portable hash' which are salted MD5 hashes. The file /wp-includes/pluggable.php outlines the call to 8192 iterations of MD5 from phpass. Remember that phpass also takes care of adding in the salt so salt is included with the hash for added security.

The use of MD5 and the final fallback of phpass for Wordpress password hashing is undoubtedly a choice of compatibility. MD5 is the only hash algorithm able to be used with older versions of PHP (way back to 3.0.x) as well as current PHP versions so that Wordpress is able to install and run on virtually any PHP installation.

Change Wordpress Default Hashing Algorithm

It is possible to change preferred algorithms for Wordpress to a stronger choice than MD5. The following page outlines the needed change to /wp-includes/pluggable.php to use to blowfish if available, then falling back to DES with 16384 iterations. All users would need to change their passwords after this edit to be rehashed with the new algorithm:

Salted MD5 with Iterations

The default salted MD5 hashes with 8192 iterations is perhaps the minimum security one would prefer for password hashes. MD5 is becoming more and more something to avoid if other options are available. For instance Linkedin passwords were stored in MD5 with no salt and were cracked easily within minutes. Salt and iterations significantly increases the strength and security, but unfortunately by still incorporating MD5, the current choice by the Wordpress project is problematic.

Tools such as "oclhashcat" are able to crack Wordpress phpass MD5 hashes with salt. This can also be done with "John the Ripper". Cracking phpass MD5 hashes is so common in the cracking community that these types of hashes have become a benchmark measurement to test GPU hardware. As GPU hardware becomes more and more powerful (and quickly available in large scale through cloud services), the time to crack hashes gets significantly lower.

The best course of action in using the default Wordpress configuration for password hashing is to use very long passwords. Passwords 24 characters in length significantly increase the time required to attempt cracking. An absolute minimum password length recommended by this author would be 12 characters in length.

Conclusions

If stronger password storage requirements are required by a company or organization in regards to running Wordpress, consider patching Wordpress to use blowfish or DES with 16384 iterations if available on the server as shown above. If this change is not possible, consider setting a password policy requiring very long passwords for Wordpress. A minimum password of 12 characters in length with 24 characters being much more secure is the recommendation of this author.

For end users browsing the web and creating user accounts on various Wordpress sites, consider that the default configuration of Wordpress is storing passwords in salted MD5 which can be cracked. If someone was to obtain the wp_users table of a website, not only do they have usernames and password hashes, but also an associated email address. It is critical to use unique passwords for every site so that if a site is compromised, a re-used password does not then become a personal security issue.

Hopefully future versions of Wordpress will consider using stronger default algorithms for password hashing now that most all servers are running at least PHP 5.3.0. Outlining that a particular Wordpress version X.x.x and later requires PHP 5.3.0 or higher for 'password security' will certainly be a well received gesture and is recommended to the Wordpress project at this point. At any rate, using very long passwords is undoubtedly the best solution no matter what hashing algorithm is in place for a given website.

One thought on “A Closer Look at WordPress Password Hashes”

If using PHP 5.3.0 or later with the Suhosin patch, phpass has the ability to hash with blowfish (CRYPT_BLOWFISH in PHP), falling back to DES hashes if using PHP 5.3.0 and no Suhosin patch (CRYPT_EXT_DES in PHP), and a final fallback to salted MD5 based hashes (known as portable hashes). phpass utilizes iterations and salt regardless of which algorithm is utilized.